Please use GitHub's private vulnerability reporting for issues that could expose credentials, overwrite user files, cross an approved path boundary, or create unsafe archives. Do not include secrets or private inventory reports in a public issue.
Use a public GitHub issue only for non-sensitive bugs and documentation problems.
Skills Manager inventory reports are local operational records. They may contain:
- absolute filesystem paths;
- Git remotes, branches, and revisions;
- Skill names, hashes, dependencies, and risk hints;
- the locations of missing references or conflicting entries.
Git remote URL credentials and URL parameters are redacted before reports are written, but reports should still be reviewed before they are shared or committed.
Security fixes are applied to the latest release. Users should update to the newest tagged version before reporting a resolved issue.